RFC 9864: Fully-Specified Algorithms for JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE)
In plain English — editorial summary, not part of the RFC
This specification refers to cryptographic algorithm identifiers that fully specify the cryptographic operations to be performed, including any curve, key derivation function (KDF), and hash functions, as being "fully specified". It refers to cryptographic algorithm identifiers that require additional information beyond the algorithm identifier to determine the cryptographic operations to be performed as being "polymorphic". This specification creates fully-specified algorithm identifiers for registered JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE) polymorphic algorithm identifiers, enabling applications to use only fully-specified algorithm identifiers. It deprecates those polymorphic algorithm identifiers. This specification updates RFCs 7518, 8037, and 9053. It deprecates polymorphic algorithms defined by RFCs 8037 and 9053 and provides fully-specified replacements for them. It adds to the instructions to designated experts in RFCs 7518 and 9053.
Document record
- Document ID
- RFC9864
- Published
- October 2025
- Authors
- M.B. Jones; O. Steele
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 16
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9865Cursor-Based Pagination of System of Cross-domain Identity Management (SCIM) ResourcesCurrent
October 2025
- RFC 9867Mixing Preshared Keys in the IKE_INTERMEDIATE and CREATE_CHILD_SA Exchanges of the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-Quantum SecurityCurrent
November 2025
- RFC 9853Return Routability Check for DTLS 1.2 and 1.3Current
March 2026
- RFC 9852New Protocols Using TLS Must Require TLS 1.3Current
July 2026
- RFC 9851TLS 1.2 is in Feature FreezeCurrent
July 2026
- RFC 9850The SSLKEYLOGFILE Format for TLSCurrent
July 2026
- RFC 9849TLS Encrypted Client HelloCurrent
March 2026
- RFC 9879Use of Password-Based Message Authentication Code 1 (PBMAC1) in PKCS #12 SyntaxCurrent
September 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?